CVE-2026-104890: Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution
Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklistedextensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP that bypasses the check and is stored in the web-accessible media directory with an executable lowercase extension. The default blacklist also omits several server-executable extension types, allowing the same code-execution impact where the web server executes uploaded files. This issue is fixed in version 7.3.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kunstmaan CMSto a version that resolves this vulnerability.Fixed in 7.3.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated backend user with access to the media upload functionality can exploit it. Exploitation does not require user interaction.
Are installations using the default extension blacklist affected?
Yes. In addition to the case-sensitive blacklist bypass using mixed-case extensions such as PHP, the default blacklist omits some extension types that web servers may execute.
What conditions are required for remote code execution?
The uploaded file must be placed in the web-accessible media directory, and the web server must be configured to execute the uploaded extension type. A successful upload is stored with a lowercased extension.
What should teams do if they cannot upgrade immediately?
Restrict media upload access to only trusted backend users and ensure the web server does not execute scripts from the web-accessible media directory. Review the configured blacklist for executable extensions supported by the web server.
How can administrators determine whether their deployment is affected?
Deployments running versions prior to 7.3.2 are affected. Review uploaded media for executable files, including files whose original upload used mixed-case extensions, in the web-accessible media directory.